2026-03-11 10:03:01 +08:00
|
|
|
import logging
|
2026-01-14 23:29:18 +08:00
|
|
|
from typing import NotRequired, override
|
2026-01-14 12:32:34 +08:00
|
|
|
|
|
|
|
|
from langchain.agents import AgentState
|
|
|
|
|
from langchain.agents.middleware import AgentMiddleware
|
|
|
|
|
from langgraph.runtime import Runtime
|
|
|
|
|
|
refactor: split backend into harness (deerflow.*) and app (app.*) (#1131)
* refactor: extract shared utils to break harness→app cross-layer imports
Move _validate_skill_frontmatter to src/skills/validation.py and
CONVERTIBLE_EXTENSIONS + convert_file_to_markdown to src/utils/file_conversion.py.
This eliminates the two reverse dependencies from client.py (harness layer)
into gateway/routers/ (app layer), preparing for the harness/app package split.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* refactor: split backend/src into harness (deerflow.*) and app (app.*)
Physically split the monolithic backend/src/ package into two layers:
- **Harness** (`packages/harness/deerflow/`): publishable agent framework
package with import prefix `deerflow.*`. Contains agents, sandbox, tools,
models, MCP, skills, config, and all core infrastructure.
- **App** (`app/`): unpublished application code with import prefix `app.*`.
Contains gateway (FastAPI REST API) and channels (IM integrations).
Key changes:
- Move 13 harness modules to packages/harness/deerflow/ via git mv
- Move gateway + channels to app/ via git mv
- Rename all imports: src.* → deerflow.* (harness) / app.* (app layer)
- Set up uv workspace with deerflow-harness as workspace member
- Update langgraph.json, config.example.yaml, all scripts, Docker files
- Add build-system (hatchling) to harness pyproject.toml
- Add PYTHONPATH=. to gateway startup commands for app.* resolution
- Update ruff.toml with known-first-party for import sorting
- Update all documentation to reflect new directory structure
Boundary rule enforced: harness code never imports from app.
All 429 tests pass. Lint clean.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* chore: add harness→app boundary check test and update docs
Add test_harness_boundary.py that scans all Python files in
packages/harness/deerflow/ and fails if any `from app.*` or
`import app.*` statement is found. This enforces the architectural
rule that the harness layer never depends on the app layer.
Update CLAUDE.md to document the harness/app split architecture,
import conventions, and the boundary enforcement test.
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* feat: add config versioning with auto-upgrade on startup
When config.example.yaml schema changes, developers' local config.yaml
files can silently become outdated. This adds a config_version field and
auto-upgrade mechanism so breaking changes (like src.* → deerflow.*
renames) are applied automatically before services start.
- Add config_version: 1 to config.example.yaml
- Add startup version check warning in AppConfig.from_file()
- Add scripts/config-upgrade.sh with migration registry for value replacements
- Add `make config-upgrade` target
- Auto-run config-upgrade in serve.sh and start-daemon.sh before starting services
- Add config error hints in service failure messages
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix comments
* fix: update src.* import in test_sandbox_tools_security to deerflow.*
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: handle empty config and search parent dirs for config.example.yaml
Address Copilot review comments on PR #1131:
- Guard against yaml.safe_load() returning None for empty config files
- Search parent directories for config.example.yaml instead of only
looking next to config.yaml, fixing detection in common setups
Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
* fix: correct skills root path depth and config_version type coercion
- loader.py: fix get_skills_root_path() to use 5 parent levels (was 3)
after harness split, file lives at packages/harness/deerflow/skills/
so parent×3 resolved to backend/packages/harness/ instead of backend/
- app_config.py: coerce config_version to int() before comparison in
_check_config_version() to prevent TypeError when YAML stores value
as string (e.g. config_version: "1")
- tests: add regression tests for both fixes
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
* fix: update test imports from src.* to deerflow.*/app.* after harness refactor
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
2026-03-14 22:55:52 +08:00
|
|
|
from deerflow.agents.thread_state import SandboxState, ThreadDataState
|
|
|
|
|
from deerflow.sandbox import get_sandbox_provider
|
2026-01-14 12:32:34 +08:00
|
|
|
|
2026-03-11 10:03:01 +08:00
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
2026-01-14 12:32:34 +08:00
|
|
|
|
|
|
|
|
class SandboxMiddlewareState(AgentState):
|
|
|
|
|
"""Compatible with the `ThreadState` schema."""
|
|
|
|
|
|
2026-01-14 23:29:18 +08:00
|
|
|
sandbox: NotRequired[SandboxState | None]
|
2026-01-15 13:22:30 +08:00
|
|
|
thread_data: NotRequired[ThreadDataState | None]
|
2026-01-14 12:32:34 +08:00
|
|
|
|
|
|
|
|
|
|
|
|
|
class SandboxMiddleware(AgentMiddleware[SandboxMiddlewareState]):
|
2026-01-17 23:23:12 +08:00
|
|
|
"""Create a sandbox environment and assign it to an agent.
|
|
|
|
|
|
|
|
|
|
Lifecycle Management:
|
2026-01-18 13:38:34 +08:00
|
|
|
- With lazy_init=True (default): Sandbox is acquired on first tool call
|
|
|
|
|
- With lazy_init=False: Sandbox is acquired on first agent invocation (before_agent)
|
2026-01-17 23:23:12 +08:00
|
|
|
- Sandbox is reused across multiple turns within the same thread
|
|
|
|
|
- Sandbox is NOT released after each agent call to avoid wasteful recreation
|
|
|
|
|
- Cleanup happens at application shutdown via SandboxProvider.shutdown()
|
|
|
|
|
"""
|
2026-01-14 12:32:34 +08:00
|
|
|
|
|
|
|
|
state_schema = SandboxMiddlewareState
|
|
|
|
|
|
2026-01-18 13:38:34 +08:00
|
|
|
def __init__(self, lazy_init: bool = True):
|
|
|
|
|
"""Initialize sandbox middleware.
|
|
|
|
|
|
|
|
|
|
Args:
|
|
|
|
|
lazy_init: If True, defer sandbox acquisition until first tool call.
|
|
|
|
|
If False, acquire sandbox eagerly in before_agent().
|
|
|
|
|
Default is True for optimal performance.
|
|
|
|
|
"""
|
|
|
|
|
super().__init__()
|
|
|
|
|
self._lazy_init = lazy_init
|
|
|
|
|
|
2026-01-15 13:22:30 +08:00
|
|
|
def _acquire_sandbox(self, thread_id: str) -> str:
|
2026-01-14 12:32:34 +08:00
|
|
|
provider = get_sandbox_provider()
|
2026-01-15 13:22:30 +08:00
|
|
|
sandbox_id = provider.acquire(thread_id)
|
2026-03-11 10:03:01 +08:00
|
|
|
logger.info(f"Acquiring sandbox {sandbox_id}")
|
2026-01-14 12:32:34 +08:00
|
|
|
return sandbox_id
|
|
|
|
|
|
|
|
|
|
@override
|
|
|
|
|
def before_agent(self, state: SandboxMiddlewareState, runtime: Runtime) -> dict | None:
|
2026-01-18 13:38:34 +08:00
|
|
|
# Skip acquisition if lazy_init is enabled
|
|
|
|
|
if self._lazy_init:
|
|
|
|
|
return super().before_agent(state, runtime)
|
|
|
|
|
|
|
|
|
|
# Eager initialization (original behavior)
|
2026-01-14 12:32:34 +08:00
|
|
|
if "sandbox" not in state or state["sandbox"] is None:
|
2026-03-25 21:01:10 +08:00
|
|
|
thread_id = (runtime.context or {}).get("thread_id")
|
|
|
|
|
if thread_id is None:
|
|
|
|
|
return super().before_agent(state, runtime)
|
2026-01-15 13:22:30 +08:00
|
|
|
sandbox_id = self._acquire_sandbox(thread_id)
|
2026-03-11 10:03:01 +08:00
|
|
|
logger.info(f"Assigned sandbox {sandbox_id} to thread {thread_id}")
|
2026-01-14 12:32:34 +08:00
|
|
|
return {"sandbox": {"sandbox_id": sandbox_id}}
|
|
|
|
|
return super().before_agent(state, runtime)
|
2026-03-11 10:03:01 +08:00
|
|
|
|
|
|
|
|
@override
|
|
|
|
|
def after_agent(self, state: SandboxMiddlewareState, runtime: Runtime) -> dict | None:
|
|
|
|
|
sandbox = state.get("sandbox")
|
|
|
|
|
if sandbox is not None:
|
|
|
|
|
sandbox_id = sandbox["sandbox_id"]
|
|
|
|
|
logger.info(f"Releasing sandbox {sandbox_id}")
|
|
|
|
|
get_sandbox_provider().release(sandbox_id)
|
|
|
|
|
return None
|
|
|
|
|
|
2026-03-25 21:01:10 +08:00
|
|
|
if (runtime.context or {}).get("sandbox_id") is not None:
|
2026-03-11 10:03:01 +08:00
|
|
|
sandbox_id = runtime.context.get("sandbox_id")
|
|
|
|
|
logger.info(f"Releasing sandbox {sandbox_id} from context")
|
|
|
|
|
get_sandbox_provider().release(sandbox_id)
|
|
|
|
|
return None
|
|
|
|
|
|
|
|
|
|
# No sandbox to release
|
|
|
|
|
return super().after_agent(state, runtime)
|